Sun Sentinel Broward Edition

Brazen ransomware gangs not afraid to target police

- By Alan Suderman

RICHMOND, Va., — Police Chief Will Cunningham came to work four years ago to find his six-officer department was the victim of a crime.

Hackers had taken advantage of a weak password to break in and encrypt the files of the department in Roxana, a small town in Illinois near St. Louis, and were demanding $6,000 of bitcoin.

“I was shocked, I was surprised, frustrated,” Cunningham said.

Police department­s big and small have been plagued for years by foreign hackers breaking into networks and causing varying level of mischief, from disabling email systems to more serious problems with 911 centers temporaril­y knocked offline.

In some cases important files have gone missing.

But things have taken a dark turn recently.

Criminal hackers are increasing­ly using brazen methods to increase pressure on law enforcemen­t agencies to pay ransoms, including leaking or threatenin­g to leak highly sensitive and potentiall­y life-threatenin­g informatio­n.

The threat of ransomware has risen to a level that’s impossible to ignore, with hardly a day going by without news of a hospital, private business or government agency being victimized. On Saturday, the operator of a major pipeline system that transports fuel across the East Coast said it had been victimized by a ransomware attack.

The increasing­ly defiant attacks on law enforcemen­t agencies underscore how little ransomware gangs fear repercussi­ons.

In Washington, a Russian-speaking ransomware syndicate called Babuk hacked into the network of the city’s police department and threatened to leak the identities of confidenti­al informants unless an unspecifie­d ransom was paid.

A day after the initial threat was posted in late April, the gang tried to spur payment by leaking personal informatio­n of some police officers taken from background checks, including details of officers’ past drug use, finances and — in at least one incident — of past sexual abuse.

Ransomware gangs have been leaking sensitive data from victims for well over a year, but experts said they’ve not seen such aggressive new tactics used before against police department­s.

Making the ransomware attacks potentiall­y more damaging, police are now able to collect and store more personal informatio­n than ever before through advances in surveillan­ce equipment and technologi­es such as artificial intelligen­ce and facial recognitio­n software.

Homeland Security Secretary Alejandro Mayorkas has called ransomware a “threat to national security” and said the issue is a top priority of the White House. Congress is exploring giving state and local government­s grant money to boost their response to ransomware.

Because ransomware is so lucrative for its perpetrato­rs, who operate out of Western law enforcemen­t’s reach in Russia and other safe havens, experts say the most important tools for battling it are elementary cybersecur­ity measures.

Statistics of how many police department­s have been hit by ransomware attacks are hard to come by, as is informatio­n on whether department­s ever pay a ransom. There’s no official count and not every incident is made public.

Brett Callow, a threat analyst at the security firm Emsisoft, said he’s counted at least 11 law enforcemen­t agencies affected by ransomware since the beginning of 2020. Officers have been locked out of their computer systems and forced to resort to paper records.

Prosecutor­s in Stuart, Florida, told local media last year they had to drop a case against suspected drug dealers after a local police department’s files were encrypted by a ransomware gang.

In the nation’s capital, the final outcome is uncertain. The Babuk gang’s threats to release more informatio­n have so far not come to pass and the files that were posted have been taken down.

Back in Roxana, the police chief said he didn’t have to pay the hackers because the files were backed up and the department bought new computer equipment for roughly the same amount as the ransom demand. Cunningham reported the hackers to the FBI, but as far as he’s heard they were never caught. The whole experience, Cunningham said, was a real eye-opener.

“It’s amazing how much opportunit­y is out there for these computer crimes,” he said.

 ?? ANDREW HARNIK/AP ?? Homeland Security chief Alejandro Mayorkas has called ransomware a “threat to national security.”
ANDREW HARNIK/AP Homeland Security chief Alejandro Mayorkas has called ransomware a “threat to national security.”

Newspapers in English

Newspapers from United States